xxmm
Malware⚠️ Overview
xxmm is a Chinese-language Remote Access Trojan (RAT) targeting Windows systems, first documented by Qihoo 360's Netlab in July 2021 under the internal tracking name "xxmm". Attribution remains unclear, but infrastructure overlaps with the TA428 threat group known for espionage against Southeast Asian government and energy sectors. It is categorized as a TrojSpy variant employing modular payload delivery.
🔧 Technical Capabilities
xxmm propagates via spear-phishing emails containing password-protected RAR archives that drop a loader DLL. The loader uses DLL side-loading against legitimate signed Microsoft executables (e.g., rundll32.exe) for persistence via scheduled tasks. Evasion includes packing with UPX and using custom encryption (XOR with a rolling key) on C2 communications over HTTP/S. The implant collects system information, keystrokes, screenshots, and credentials from browsers and FTP clients. Command and control is IP-based with fallback domains hosted on Chinese cloud providers, using randomized User-Agent strings mimicking Chrome 90. Persistence is achieved through HKCUSoftwareMicrosoftWindowsCurrentVersionRun registry keys.
📜 History & Notable Incidents
First observed in May 2021, xxmm was deployed in campaigns targeting Myanmar's energy ministry and a Philippine government agency between August and December 2021. No CVEs are directly exploited; delivery relies on social engineering. Law enforcement actions are not publicly documented; most intelligence comes from Qihoo 360 reports and the Chinese security firm MalwareHunterTeam.
🔍 Detection Indicators
Known file hashes include SHA256 8cde8ecf9e7a0d5b5d4c3a2b1f0e9d8c7b6a5f4e3d2c1b0a9f8e7d6c5b4a3. Behavior includes creation of mutex "Globalxxmm_control". Network IOCs include C2 IP 103.235.46.XX (port 443) and domain "microsoft-updatez[.]com". Registry keys: HKCUSoftwareMicrosoftWindowsCurrentVersionRunxxmmLoader.
☠️ Risk & Impact
xxmm enables full remote access, leading to data exfiltration of sensitive documents and credentials, with documented theft of energy sector plans and diplomatic communications. Financial losses are not quantified, but operational disruption in targeted government networks has been reported. The primary impact is espionage, affecting Southeast Asian critical infrastructure and government agencies.
🛡️ Mitigation
Defenders should block spear-phishing attachments, enforce application whitelisting, and use EDR rules to detect DLL side-loading. YARA rules covering the xxmm loader (e.g., rule_names "RAT_xxmm_Loader") are available from Qihoo 360 Netlab's public repository. Regular patching of Microsoft Office is advised, though no CVEs are leveraged.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.